CVE-2020-14190: Atlassian Crucible

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.

Affected products

  • Atlassian Crucible: before 4.8.4 (fixed in 4.8.4)
  • Atlassian Fisheye: before 4.8.4 (fixed in 4.8.4)

Published 2020-11-25. Last modified 2026-06-17.